Skip to content
← LibraryTechnique entry
CI-SECRET-IN-LOGCredential Access

Secret Echo to Build Log

Workflow inadvertently prints a secret (echo $SECRET, set -x, env dump) — public CI log exposes it.

§ Where this technique fits

CI-SECRET-IN-LOG is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 5 approved dossiers in the registry, typically at step 4.6 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    AWS sts:AssumeRole Chain
    C-AWS-ASSUMEROLE-CHAIN · Lateral Movement
    seen 1×
  2. 02
    Valid Accounts
    T1078 · Initial Access
    seen 1×